GitPython 在 3.1.59 版本之前存在一个不安全的问题:在 检查中使用的拒绝列表不完整,遗漏了对 和 选项的防护。攻击者可以通过向 方法传递这些选项,读取任意文件。例如,攻击者可以传入类似 的修订值,从而通过 操作返回的结果泄露文件内容。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| gitpython-developers | GitPython | < 3.1.59 |
affected |
3.1.59 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| gitpython-developers | GitPython | 0 ~ 3.1.59 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-78676 | 9.8 CRITICAL | GitPython before 3.1.59 Remote Code Execution via Config Injection |
| CVE-2026-78675 | 8.4 HIGH | GitPython before 3.1.59 Local File Content Disclosure via .gitmodules |
| CVE-2026-78677 | 7.5 HIGH | GitPython before 3.1.59 Path Traversal via separate-git-dir |
| CVE-2026-78679 | 6.5 MEDIUM | GitPython before 3.1.59 Arbitrary File Read via TagReference.create |
No comments yet